-
Notifications
You must be signed in to change notification settings - Fork 11.9k
Vite security vulnerability #32945
Copy link
Copy link
Closed
Labels
area: @angular/buildgemini-triagedLabel noting that an issue has been triaged by geminiLabel noting that an issue has been triaged by geminiseverity6: security
Description
Command
other
Is this a regression?
- Yes, this behavior used to work in the previous version
The previous version in which this bug was not present was
No response
Description
There is a reported security vulnerability in Vite 7.3.1 (GHSA-p9ff-h696-f583). The latest @angular/build version 21.2.6 still depends on Vite 7.3.1, which introduces a transitive dependency vulnerability in Angular CLI projects.
Related issue - GHSA-v2wj-q39q-566r
Minimal Reproduction
N/A
Exception or Error
vite@7.3.1 – Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket (high severity)
Your Environment
21.2.5
Anything else relevant?
No response
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
area: @angular/buildgemini-triagedLabel noting that an issue has been triaged by geminiLabel noting that an issue has been triaged by geminiseverity6: security